Controllers must conduct and document data protection assessments for processing that presents a heightened risk of harm: targeted advertising, sale, sensitive-data processing, and profiling presenting specified risks; the AG may require disclosure.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.